Live data from Hacker News

Boffins reveal password-killer 0days for iOS and OS X

theregister.co.uk

51–60 of 144 posts

Re: Boffins reveal password-killer 0days for iOS and OS X

#51
post #36
post #34

Earlier quoted context omitted.

Rootless is more about securing the OS files and processes from malware.

Isn't this similar? Rootless is strengthening the sandbox against malware. Anyone on the new Mac version want to test this?

It seemed to me like rootless was at a lower level than the sandbox, since arbitrary apps don't run in the sandbox.

Re: Boffins reveal password-killer 0days for iOS and OS X

#52
post #9

Anyone have any more information about (or even a source for) "Google's Chromium security team was more responsive and removed Keychain integration for Chrome noting that it could likely not be solved at the application level"? Is this going to happen in an upcoming stable release? What is it being replaced with?

That does seem a bit strange. The Chrome devs have long taken the position that there's no point trying to encrypt local copies of passwords. You can see a very long discussion about it here where Chrome devs argue that it's pointless: https://news.ycombinator.com/item?id=6165708

The comments by the chrome security tech lead would suggest that they wouldn't view this keychain issue as a security flaw.

So I don't see why they would bother removing keychain integration. What is the replacement going to be? A password file encrypted with the password "peanuts"?[1]

[1] https://news.ycombinator.com/item?id=9714770

Re: Boffins reveal password-killer 0days for iOS and OS X

#53
post #35

The fundamental design flaw of all of these compromised password managers, keychains, etc. is that they keep state in a file. That causes all sorts of problems (syncing among devices, file corruption, unauthorized access, tampering, backups, etc.). Edit - I seldom downvote others and the few times I do, I comment as to why I think the post was inappropriate. What is inappropriate about my post? Few people stop and th…

No idea. I can't even find a single obvious interpretation of what a downvote is supposed to convey. I bet it's not the same thing twice for the same person on the same day. If it were up to me, I would remove the power-to-downvote from the API. If I really do oppose a comment, I should give a reason rather than just a “bit with a negative sign”.

One reason is people using HN on mobile devices. This used to be my "reading account" so I couldn't downvote accidentally but now I have crossed the barrier with this one as well.

Not saying that is what happened here though (because I down't know.)

Re: Boffins reveal password-killer 0days for iOS and OS X

#54
post #31

Earlier quoted context omitted.

Yes, but the researchers submitted an app with the exploit to the app store, and it was accepted.

Good thing there are 1,500,000 apps in the store and getting visibility is the biggest challenge for developers/publishers :-)

"MoneyMakingApp5000 - make money from home"

Post some screenshots of the app with screenshots of some random Paypal transfers and I don't think that you will have a problem getting people to find/download your app.

Re: Boffins reveal password-killer 0days for iOS and OS X

#55

Once again goes to show that Apple is mostly interested in the security of its iStore, platform lock down and DRM. I'm not exactly shocked. Just for kicks... Does anyone remember the I'm a PC ads, where macs were magically "secure", couldn't get viruses or hacked or anything? Turns out, with marketshare they can! Just like Windows. Strange thing eh?

>Just like Windows. Strange thing eh? Not strange if you grasp the fact that malware is just a program that has elevated access. For me it was strange how can Apple market their system as virus-free. Now that's ridiculous.

Yes, to any techie the lie is obvious.

I just wonder what the vast userbase of uneducated people (seniors, teen bloggers, ironically education institutions, etc) who moved over to macs because they bought the lie will feel when they too later discover that the promises were a lie.

Because unlike Microsoft, Apple doesn't have a battle hardened OS where security has been worked on systematically, for over a decade.

And I could have told you the same story years ago. I don't need blatantly obvious bugs like this one to back that claim.

Re: Boffins reveal password-killer 0days for iOS and OS X

#56
post #31

Earlier quoted context omitted.

Yes, but the researchers submitted an app with the exploit to the app store, and it was accepted.

Good thing there are 1,500,000 apps in the store and getting visibility is the biggest challenge for developers/publishers :-)

Ah yes, security by obscurity, everyone's favourite.

Re: Boffins reveal password-killer 0days for iOS and OS X

#58

Once again goes to show that Apple is mostly interested in the security of its iStore, platform lock down and DRM. I'm not exactly shocked. Just for kicks... Does anyone remember the I'm a PC ads, where macs were magically "secure", couldn't get viruses or hacked or anything? Turns out, with marketshare they can! Just like Windows. Strange thing eh?

>Just like Windows. Strange thing eh? Not strange if you grasp the fact that malware is just a program that has elevated access. For me it was strange how can Apple market their system as virus-free. Now that's ridiculous.

I have never seen Apple market their system as "virus free". Can you point me to that one?

Re: Boffins reveal password-killer 0days for iOS and OS X

#59
post #47
post #35

The fundamental design flaw of all of these compromised password managers, keychains, etc. is that they keep state in a file. That causes all sorts of problems (syncing among devices, file corruption, unauthorized access, tampering, backups, etc.). Edit - I seldom downvote others and the few times I do, I comment as to why I think the post was inappropriate. What is inappropriate about my post? Few people stop and th…

Where should the state be kept, on a server?

No where electronically. A simple word or phrase in the user's mind would do.

Rather than being stored for later retrieval, complex passwords could be generated on-the-fly (when needed) using this word/phrase as input combined with other input such as URLs, hostnames, service names, etc.

Re: Boffins reveal password-killer 0days for iOS and OS X

#60
post #28

So Apple was aware of this for 6 months and are doing NOTHING, not even communicating?! How serious do they take security and fixing it (at least within 6 months) ?

I'm surprised that you're surprised! After The Fappening and the SMS of doom (amongst many others), you can't still believe that Apple gives a sh*t about security, can you? I mean, I understand that there are still a lot of Apple fans here at HN, but Apple's security has been a laughing stock of the industry for a while now.

Don't forget 'goto fail'.
Post reply on HN